nerdexam
(ISC)2

CSSLP · Question #252

In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199. What levels of potential impact are defined by FIPS 199? Each correct answer represents a complete…

The correct answer is B. Medium C. High D. Low. FIPS 199, 'Standards for Security Categorization of Federal Information and Information Systems,' defines specific impact levels for information systems.

Secure Software Deployment, Operations, Maintenance

Question

In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199. What levels of potential impact are defined by FIPS 199? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AModerate
  • BMedium
  • CHigh
  • DLow

How the community answered

(34 responses)
  • A
    12% (4)
  • B
    88% (30)

Why each option

FIPS 199, 'Standards for Security Categorization of Federal Information and Information Systems,' defines specific impact levels for information systems.

AModerate

While 'Moderate' is the precise term used in FIPS 199 for the intermediate impact level, in the context of the provided choices and correct answer, 'Medium' is presented as the intended designation for this level, making 'Moderate' a distinct, unselected option.

BMediumCorrect

Medium represents an intermediate level of adverse effect on organizational operations, organizational assets, or individuals in the event of a security breach.

CHighCorrect

High signifies a severe or catastrophic adverse effect from a security incident.

DLowCorrect

Low indicates a limited adverse effect from a security breach. These three categories-Low, Medium (used here as an alternative to Moderate), and High-define the spectrum of potential impact according to FIPS 199 guidelines for categorizing information systems.

Concept tested: NIST FIPS 199 impact levels

Source: https://csrc.nist.gov/publications/detail/fips/199/final

Topics

#NIST FIPS 199#Impact Levels#Certification & Accreditation#Risk Management Framework

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice